Impact
A vulnerability in the installation and configuration component of Oracle Hyperion Infrastructure Technology allows a low‑privileged attacker with network access via HTTP to compromise the entire system. Successful exploitation can lead to a full takeover, affecting confidentiality, integrity, and availability. The CVSS 3.1 Base Score of 7.5 indicates high severity and substantial impacts across all three pillars.
Affected Systems
Oracle Hyperion Infrastructure Technology, version 11.2.25.0.000, is the only affected version according to the vendor.
Risk and Exploitability
The vulnerability can be exploited over the network using standard HTTP traffic, requiring only low privileges. The EPSS score of < 1% indicates a low probability of exploitation, yet the 7.5 CVSS score reflects that a successful attack would result in significant damage. The vulnerability is not listed in CISA KEV, but its potential for complete system compromise makes it a high priority for mitigation.
OpenCVE Enrichment